Self-Custody
Self-custody is an arrangement in which the user alone holds the private keys and no service can move the assets. A provider may build the wallet, host the interface and broadcast the transaction, but if it cannot produce a signature, the balance is beyond its reach.
Also called: non-custodial · unhosted · self-hosted
What self-custody actually requires
Keys are generated on the user’s own device and never leave it in a form the provider can use. The provider holds no copy, no escrow key and no recovery key. If the wallet uses multi-party computation, the provider’s shards sit below the signing threshold, so it cannot assemble a signature without the user. If it is a smart-contract wallet, no administrative key lets the provider upgrade, freeze or sweep it.
Each of those is a factual question with a checkable answer, and several widely marketed “non-custodial” products fail at least one of them. A recovery service that can restore a wallet without the user is holding something that can move the assets.
Why non-custodial does not mean unregulated
Custody is one regulated activity among several, and it is not analyzed the same way everywhere. In the United States, FinCEN’s convertible-virtual-currency guidance turns on facts rather than labels: a multiple-signature wallet provider that never has total independent control over the value is not a money transmitter, but only for as long as it restricts its role to that. A provider that also runs hosted wallets, or that holds the value as an entry in its own accounts, is a money transmitter regardless of the label it applies to itself, and a decentralized application that accepts and transmits value is one too. In the European Union, custody is only one of the ten crypto-asset services MiCA lists: exchanging crypto-assets for funds or for other crypto-assets, operating a trading platform, executing or transmitting orders and providing transfer services each require authorization with no custody involved at all.
So holding no keys removes one trigger; it does not end the analysis. A service that routes every trade, sets the price and holds the fiat while signing nothing may still sit squarely inside a regime aimed at intermediaries, while a genuinely passive piece of software may not. Which way it falls depends on the country’s own definitions, which is a question worth settling in writing before a launch rather than after one. The opposite arrangement, where the provider does hold the keys, is crypto custody, and the wallet on the user’s side of it is an unhosted wallet.
In practice
Being non-custodial narrows licensing exposure; it does not automatically remove it, and it is not assessed the same way in every country. In the United States the test is control in fact rather than the label a service gives itself, and the exemption for a multiple-signature provider holds only while it restricts its role to that function. In the European Union, custody is one of ten crypto-asset services under MiCA — exchange, running a trading platform, executing or transmitting orders and transfer services all require authorization without it.
Example
A wallet app generates keys on the customer’s phone and never sees them. The same app also lets customers sell tokens for dollars, with the operating company taking the crypto and instructing the bank payment. The wallet is genuinely self-custodial. The off-ramp is a separate service, and it is that service, not the wallet, the licensing question attaches to.
Commonly confused with
| Term | How it differs |
|---|---|
| Crypto Custody | Custody means a third party can sign; self-custody means only the user can, which is a question about keys rather than about what the service is called. |
| Unhosted Wallet | Unhosted wallet is the regulatory label for the wallet itself; self-custody describes the arrangement, including institutional setups with no consumer wallet in sight. |
See also
- Crypto CustodyCrypto custody is holding someone else’s crypto-assets, or the means of access to them, in a way that lets you move them. The test is control in fact — who could move the balance without the customer’s cooperation — not how the service describes itself in its terms.
- Unhosted WalletAn unhosted wallet is a wallet whose private keys are held by the user, with no service in a position to move the funds. Regulators use the term mainly to describe the far end of a transfer: a counterparty that is a person and a device rather than a firm.
- Hosted WalletA hosted wallet is a wallet where a service holds the private keys on the user’s behalf. The user sees a balance and can instruct a transfer, but the provider is the party that signs, and the provider’s records are what the balance actually rests on.
- Virtual Asset Service ProviderA virtual asset service provider, or VASP, is the FATF category for a business that exchanges, transfers, safekeeps or administers virtual assets for other people, or provides financial services around their issuance. It is an international standard-setter’s term, not a license.
